1

Isso Issm Jobs in Virginia (NOW HIRING)

Apply deep expertise in RMF, NIST 800-53, Continuous Monitoring (ConMon), ISSO/ISSM practices, and secure workstation engineering to ensure compliant implementation * Lead the day-to-day team ...

next page

Showing results 1-20

Isso Issm information

What is an Information Systems Security Officer (ISSO)?

Information System Security Officers (ISSOs) and Information System Security Managers (ISSMs) are cybersecurity professionals responsible for the protection and oversight of information systems within an organization, particularly in compliance-driven environments like government or defense. ISSOs focus on the day-to-day security operations, monitoring, and implementation of security controls, while ISSMs are typically responsible for the overall security program management and ensuring compliance with relevant regulations and policies. Both roles are crucial for maintaining the confidentiality, integrity, and availability of sensitive data.

What are the key skills and qualifications needed to thrive as an ISSO or ISSM?

To thrive as an ISSO/ISSM, you need a solid understanding of cybersecurity principles, risk management frameworks (such as NIST RMF), and compliance requirements, usually supported by a degree in information security or a related field. Familiarity with security tools like SIEM systems, vulnerability scanners, and certifications such as CISSP or Security+ are typically required. Strong analytical thinking, attention to detail, and the ability to communicate complex security concepts to diverse audiences are essential soft skills. These skills ensure the effective protection of organizational assets, compliance with regulations, and the ability to respond proactively to evolving security threats.

What are the main challenges faced by an ISSO or ISSM when working with cross-functional teams?

ISSO/ISSMs often collaborate with IT, compliance, and business units to ensure security policies align with organizational goals. A common challenge is bridging the communication gap between technical and non-technical stakeholders to ensure security requirements are understood and implemented effectively. Additionally, balancing strict security controls with operational needs requires negotiation and adaptability. Building strong relationships and maintaining clear documentation are key to overcoming these challenges and ensuring a secure and compliant environment.

What is the difference between Isso Issm vs Project Manager?

AspectIsso IssmProject Manager
CertificationsTypically requires ISSM certification, security clearancesOften requires PMP or CAPM certifications
Work EnvironmentPrimarily in cybersecurity, information systems securityIn various industries managing projects across departments
Industry UsageCommon in defense, government, IT security sectorsWidely used across construction, IT, healthcare, and more

While both roles involve managing technical aspects, Isso Issm focuses on information security management within cybersecurity environments, often requiring specific security certifications. Project Managers oversee a broad range of projects across industries, emphasizing planning, execution, and delivery. Understanding these differences helps clarify career paths and employer expectations in respective fields.

What job categories do people searching Isso Issm jobs in Virginia look for?

The top searched job categories for Isso Issm jobs in Virginia are:

What cities in Virginia are hiring for Isso Issm jobs?

Cities in Virginia with the most Isso Issm job openings:

Infographic showing various Isso Issm job openings in Virginia as of September 2026, with employment types broken down into 90% Full Time, 5% Part Time, 4% Contract, and 1% Nights. Highlights an 89% Physical, 3% Hybrid, and 8% Remote job distribution.

Information System Security Officer (ISSO)

Ashburn, VA โ€ข On-site

Federal Staffing Solutions Inc.
Business Management Consultingย โ€ขย 11 - 50 employees

$150K - $180K/yr

Other

Posted 8 days ago


Job description

Information System Security Officer (ISSO)

Full time | Federal Staffing Solutions Inc. | United States

Posted On 09/04/2026

Job Information

Technology

City Ashburn

State/Province Virginia

20146

Job Description

We connect our employees with some of the best opportunities around.

Time and again, our employees tell us that the most important thing we offer is respect. Federal Staffing Solutions puts people to work in all types of jobs. When you work with us, you build a relationship with a team of employment professionals in your community who have, in turn, built professional relationships with the businesses that are hiring.

We are looking for an ISSO to work in Ashburn, VA supporting our client.

Location: Ashburn, VA

Clearance: Secret Clearance (or able to obtain)

Salary Rate: $150,000-$180,000

Position Summary:

Our client is seeking an experienced Information System Security Officer (ISSO) to support a U.S. Customs and Border Protection (CBP) program in Ashburn, VA. The ISSO will serve as the principal point of contact for the security posture of one or more assigned information systems, ensuring compliance with DHS, CBP, and NIST cybersecurity policies throughout the system's lifecycle. This role works closely with the Information System Security Manager (ISSM), Authorizing Official (AO), system owners, and technical teams to maintain a strong Risk Management Framework (RMF) posture and support continuous authorization to operate (ATO).

Key Responsibilities:

  • Serve as the primary ISSO for assigned CBP information systems, acting as the liaison between the ISSM, AO, system owners, and technical staff on all security-related matters.
  • Execute the NIST Risk Management Framework (RMF) lifecycle, including system categorization, security control selection, implementation, assessment, authorization, and continuous monitoring.
  • Develop, update, and maintain security authorization artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Contingency Plans, and Risk Assessments.
  • Support Assessment and Authorization (A&A) activities and coordinate Security Control Assessments (SCAs) with independent assessors.
  • Monitor and track POA&M remediation activities, ensuring vulnerabilities are addressed within DHS/CBP-mandated timeframes.
  • Conduct continuous monitoring activities in accordance with DHS 4300A / CBP security policy and the organization's Information Security Continuous Monitoring (ISCM) strategy.
  • Review vulnerability scan results (e.g., Nessus, ACAS) and coordinate remediation with system administrators and engineering teams.
  • Support incident response activities for assigned systems, including detection, reporting, and coordination with the Security Operations Center (SOC).
  • Ensure system configurations align with applicable security baselines (e.g., DISA STIGs, CIS Benchmarks) and DHS/CBP policy.
  • Participate in Configuration Control Board (CCB) activities to assess the security impact of proposed system changes.
  • Prepare for and support audits, inspections, and compliance reviews conducted by DHS, CBP, or external oversight bodies.
  • Maintain awareness of, and ensure compliance with, applicable federal cybersecurity laws, regulations, and guidance, including FISMA, NIST SP 800-53, and FIPS publications.

Required Qualifications:

  • Ability to obtain and maintain a CBP Background Investigation (BI) / Public Trust clearance; existing favourable CBP or DHS suitability determination preferred.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience in lieu of degree.
  • Minimum of 3โ€“5 years of handsโ€‘on experience performing ISSO, ISSM, or comparable information systems security duties on federal information systems.
  • Working knowledge of the NIST Risk Management Framework (RMF), NIST SP 800-37, and NIST SP 800-53 security controls.
  • Familiarity with DHS 4300A Sensitive Systems Policy or equivalent federal agency security policy.
  • Experience preparing or maintaining ATO documentation (SSP, SAR, POA&M, Contingency Plan).
  • Strong written and verbal communication skills, with the ability to translate technical risk into terms understandable to non-technical stakeholders.

Required Certifications:

Candidates must hold, at minimum, both of the following certifications at time of application (in accordance with DoD 8570.01-M / DoD 8140 IAM Level II requirements):

  • Certified Information Systems Security Professional (CISSP)

Preferred Qualifications:

  • Prior experience directly supporting CBP, DHS, or another federal law enforcement/homeland security agency.
  • Additional certifications such as CAP, CISM, CEH, or Cloud+.
  • Experience with cloud environments (AWS GovCloud, Azure Government) and associated FedRAMP/ATO requirements.
  • Experience with GRC and vulnerability management tooling (e.g., Xacta, CSAM, Nessus/ACAS, Splunk).
  • Active DHS/CBP Entry-on-Duty (EOD) or current CBP suitability determination.

Equal Opportunity Employer

Federal Staffing Solutions Inc. is an Equal Opportunity Employer and does not discriminate on the basis of race or ethnicity, religion, sex, national origin, age, veteran disability or genetic information or any other reason prohibited by law in employment.

#J-18808-Ljbffr